漏洞标题
弱JSONWeb Token(JWT)秘密在CasaOS中
漏洞描述信息
CasaOS中的弱JSON Web Token(JWT)密钥
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
认证机制不恰当
漏洞标题
Weak json web token (JWT) secrets in CasaOS
漏洞描述信息
CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentication and execute arbitrary commands as `root` on CasaOS instances. This problem was addressed by improving the validation of JWTs in commit `705bf1f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
认证机制不恰当
漏洞标题
CasaOS 授权问题漏洞
漏洞描述信息
CasaOS是一个简单、易用、优雅的开源家庭云系统。 CasaOS 0.4.4之前版本存在授权问题漏洞。攻击者利用该漏洞可以制作任意JWT和访问通常需要身份验证的功能,并以root身份执行任意命令。
CVSS信息
N/A
漏洞类别
授权问题